BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0007 ✕ technique: T1040 ✕
Download CSV Show ATT&CK heatmapNetwork Packet Capture: tshark/tcpdump Informational Discovery
Network packet capture using tshark\tcpdump utility.
Indicator:Process action type = execution AND target process name = tcpdump , tshark Host host os = linux
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Network Sniffing (T1040)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Potential Network Sniffing Informational Credential Access
Network sniffing related processes were detected.
Indicator:Process action type = execution AND target process name = wireshark , tcpdump
ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)ATT&CK techniques: Network Sniffing (T1040)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11